This notice is issued under article 10 of Turkish Law no. 6698 on the Protection of Personal Data ("KVKK") and the related Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform.
1. Identity of the data controller
Medonay operates a middleware service, reachable at medonay.com and medonay.com.tr, that digitises provisioning communication between private hospitals and private health insurers.
Contact: kvkk@medonay.com.tr
2. Scope: three distinct relationships
Medonay's position towards personal data depends on whose data it is. This distinction determines who you address your rights to, which makes it the most important section of this notice.
| Whose data | Medonay's role | Where to apply |
|---|---|---|
| Website visitor, demo requester | Data controller | Medonay |
| Panel user (hospital / insurer staff) | Data controller | Medonay |
| Patient (provisioning record) | Data processor | The hospital or the insurer |
The third row matters most. For patient data processed during provisioning, the data controller is the hospital or insurer we serve. Medonay processes that data solely on that institution's instructions and under a data processing agreement with it; we do not determine the purposes or means of processing. As a patient, you exercise your rights with the hospital that treated you or the insurer that holds your policy. Requests of this kind that reach us are forwarded to the relevant institution and you are told that we did so.
3. Website visitors and demo requests
Data processed
- Identity and contact: full name, business email, phone number
- Business information: company name, company type (hospital / insurer / other), the message you send in the form
- Transaction security: IP address, browser and device information, request timestamp
Purposes and lawful bases
| Purpose | Lawful basis (KVKK art. 5) |
|---|---|
| Answering the demo request, establishing contact | 5/2-f, legitimate interest: responding to your commercial enquiry |
| Conducting pre-contractual discussions | 5/2-c, directly related to the formation of a contract |
| Site security, abuse and attack prevention | 5/2-f, legitimate interest |
| Running non-essential cookies | 5/1, explicit consent given through the cookie banner |
We do not use the details you submit through the demo form to send you marketing messages. Should we ever want to, separate and explicit consent will be requested.
4. Panel users
For employees of the hospitals and insurers using our service we process:
- Identity and contact: full name, email address
- Organisational information: the organisation you belong to, your panel role
- Transaction security: login records, IP address, timestamps, and an audit record of every state-changing action you perform in the panel
Lawful bases: KVKK art. 5/2-c (performance of the contract concluded with your institution) and art. 5/2-ç (compliance with our legal obligations). Audit records exist so that provisioning decisions can be reviewed afterwards, and they cannot be deleted.
5. Patient data processed during provisioning
This section describes, for transparency, the processing Medonay carries out as a data processor. For this data the controller is the hospital or insurer we serve.
The data minimisation we apply
- The Turkish national ID number is never stored in the clear. It is hashed with SHA-256 together with a secret key at the point of entry; the database holds only that hash plus the last four digits for on-screen display. The plaintext number appears in no record, no audit trail and no API response.
- Procedure and diagnosis codes, which constitute health data, are processed only to the extent needed to reach a provisioning decision.
- Each organisation's data is logically segregated; no institution can reach another's records.
Traceability of decisions
Every provisioning decision is stored together with the engine version that produced it, the input data, and a step-by-step trace showing which coverage and which rule was applied. This record is required so that a decision can be audited later, and it cannot be altered.
6. Recipients
Your data is processed by the service providers below so that the service can be delivered. None of them may use it for their own purposes.
| Service provider | Function | Data involved |
|---|---|---|
| Google Cloud (Cloud SQL, Cloud Run) | Application and database hosting | All service data |
| Vercel | Hosting of the web interface | Access logs, IP address |
| Cloudflare | DNS, TLS and security layer in front of the API | Request content in transit, IP address |
| Resend | Sending transactional email | Email address, name, message body |
| Google Workspace | Corporate email | Email correspondence |
| TalkOmni | Chat assistant on the website | Chat content, session identifier |
The TalkOmni chat assistant loads only if you consent through the cookie banner. Without consent it is never executed. TalkOmni is a separate product operated by the same legal entity as Medonay and runs at the same cloud provider, in the same region. It is present only on the marketing site and does not run in the management panel.
A detailed list of what each provider processes, where the data sits, and our change notification commitment: Sub-processors.
Beyond these, your personal data may be transferred only to public authorities legally empowered to request it, within the limits the legislation prescribes.
7. Transfer abroad
Our application servers and database run in Google Cloud's europe-west1 (Belgium) region. The web interface is hosted on Vercel; API traffic passes through the Cloudflare network, and account and security emails are sent through Resend, which is based in the United States. Your personal data is therefore processed outside Turkey.
Work to put in place the legal mechanism required by article 9 of the KVKK for transfers abroad is ongoing. This notice will be updated, with a new version number and effective date, once that work concludes. Migrating to a Turkey region also remains an option.
8. Retention periods
| Data | Period |
|---|---|
| Demo request records | Up to 2 years if it does not turn into a contract |
| Panel user accounts | For the term of the contract with your institution, then 10 years |
| Provisioning decisions and decision trace | 10 years, as required by insurance legislation |
| Audit records | At least 7 years |
| System and error logs | 90 days |
| Cookie consent preference | 1 year |
At the end of the period data is deleted, destroyed or irreversibly anonymised.
9. Your rights
Under article 11 of the KVKK you have the right to: learn whether your personal data is processed; request information if it is; learn the purpose of processing and whether the data is used in line with that purpose; know the third parties to whom it is transferred in Turkey or abroad; request rectification if it is incomplete or incorrect; request erasure or destruction; request that rectification and erasure be notified to the third parties the data was transferred to; object to a result arrived at solely through automated analysis that works against you; and claim compensation if you suffer damage due to unlawful processing.
For how to apply and what your application must contain, see How to submit a data subject request.
10. Security measures
- All traffic is encrypted in transit; access to the panel requires authentication.
- Passwords are stored only in an irreversible hashed form.
- API keys issued for machine access are stored hashed, can be revoked, and can be restricted to given IP ranges.
- Cross-organisation data access is blocked in the software layer and that block is continuously verified by automated tests.
- Every state-changing action produces an audit record that cannot be altered retrospectively.
- Notifications sent to external systems are signed; inbound notifications whose signature cannot be verified are not processed.
11. Changes to this notice
When this notice is updated its version number and effective date change. Panel users are informed again at their next sign-in whenever the version changes.